Effective Date: June 25, 2026 · Last Updated: September 29, 2026
AdLume ("we," "us," "our") respects your privacy. This Privacy Policy explains what personal data and business data we collect, why we collect it, how we use it, and what rights you have when you use AdLume, Lumy, our website, application, integrations, communication workflows, and paid plans (together, the "Service").
Data Controller:
Marek Dąbrowski, conducting business as AdLume
NIP: 1133071063
ul. Stawki 2a/38, 00-193 Warsaw, Poland
Email: contact@adlume.co
This Policy is intended to support compliance with the General Data Protection Regulation (GDPR) (EU 2016/679), applicable Polish data protection law, and other privacy rules that may apply to our users.
This Policy does not replace any data processing agreement, platform-specific terms, or additional agreement we may sign with business customers.
When you create an account, buy a plan, contact us, or use the Service, we may collect:
Payments are processed by Stripe. We do not store your full credit card number. We may receive:
When you connect or authorize Google Ads or Meta Ads, the Service may access and process data from those accounts. It may also process messages related to the Service in Slack. Additional advertising, analytics, tracking, marketing, or commerce tools may be supported later; this sentence does not imply they are available now.
Depending on the integration and permissions you approve, this may include:
We do not ask for your Google password or other third-party account passwords. Where available, access is granted and revoked through the provider's OAuth, API, workspace, or authorization system. Section 6 covers Google Ads and Meta Ads data in more detail.
If you use Lumy inside Slack, we may process:
To provide AI-powered analysis and recommendations, we may process:
We do not intentionally send raw credentials, OAuth tokens, API keys, or payment card numbers to AI model providers.
We may automatically collect:
We may use analytics, advertising, and tracking tools such as GA4, PostHog, Meta Pixel, and similar tools to understand website usage, improve the Service, measure campaigns, and support marketing. Depending on your settings and consent requirements, this may include cookies, pixels, device identifiers, event data, page views, referral data, and campaign attribution.
If you subscribe to our newsletter or marketing communications, we may process your email address, preferences, sign-up source, campaign engagement, and related metadata through MailerLite.
If you contact us by email, chat, form, social media, or another channel, we may retain the content of that communication, related metadata, and any follow-up actions.
We use data to:
We also create aggregated and de-identified data from the data described above, including performance patterns, benchmarks, and records of which recommendations were accepted, rejected, or produced a measurable result. Such data is stripped of anything identifying you, your business, your accounts, or any individual, and may be combined with data from other customers to evaluate, benchmark, and improve the Service, including after your subscription ends. We do not disclose your data itself to other customers, and we do not publish benchmarks in a form that allows you or your accounts to be identified.
We do not sell your personal data.
For users in the EU/EEA, UK, or other jurisdictions with similar legal basis requirements, we rely on the following bases:
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Providing the Service | Account data, connected tool data, communication data, AI inputs/outputs | Contract performance (Art. 6(1)(b)) |
| Payments, renewals, refunds, invoicing | Payment and billing data | Contract performance (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Product security, abuse prevention, logs | Usage, technical, security data | Legitimate interests (Art. 6(1)(f)) |
| Product improvement and internal analytics | Usage data, feature data, support data | Legitimate interests (Art. 6(1)(f)) or consent where required |
| Website analytics and advertising pixels | Cookies, event data, attribution data | Consent where required; legitimate interests where allowed |
| Marketing emails | Email, preferences, engagement data | Consent (Art. 6(1)(a)) or legitimate interests where allowed for existing customer communications |
| Legal, tax, accounting, compliance | Billing, contracts, support, logs | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
We use third-party service providers to operate the Service. They process data only for the purposes we authorize and subject to their own contracts, policies, and applicable law.
| Provider / Category | Purpose | Notes |
|---|---|---|
| Google Ads | Connected advertising account access and campaign data | Scope depends on account authorization |
| Windsor.ai | Meta Ads account connection, advertising data retrieval and approved changes | Current connection path for existing Meta Ads customers; connected account data passes through this provider |
| Meta Ads (direct connection) | Connected advertising account access, campaign data and approved changes, without an intermediary | Being introduced alongside Windsor.ai; scope depends on the permissions you grant |
| Anthropic (via Amazon Bedrock) | AI analysis of connected account data and recommendations | Accessed through Amazon Bedrock in the EU |
| Amazon Web Services (AWS) | Application backend, database, logs, transactional email and Amazon Bedrock inference | Region eu-central-1 (Frankfurt, Germany) |
| Stripe | Payments, subscriptions, refunds, invoices, tax and billing support | Payment card data is handled by Stripe |
| MailerLite | Email marketing and newsletter communications | Used for opted-in or permitted email communications |
| Slack | Communication, approvals and notifications | Only where enabled or connected |
| Analytics and advertising tools such as GA4, PostHog, Meta Pixel | Website/product analytics, attribution, performance measurement and remarketing where enabled | Consent may be required depending on jurisdiction |
| Cloudflare | Public website hosting, delivery, DNS, security and related web infrastructure | Used for the public website |
When you connect Google services, our use and transfer of data received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements, where applicable.
We use Google user data only to provide and improve user-facing features of the Service, including account analysis, recommendations, approved actions, reporting, monitoring, support, and security.
We do not use Google user data for:
We do not share Google Ads data except as needed to provide the Service, comply with law, protect security, or as described in this Policy.
You may revoke Google access through your Google Account settings or through the Service where supported.
You can connect a Meta Ads account in one of two ways:
For a direct connection, you sign in on Meta's own screen and approve the permissions there. We never see your Facebook password. The direct connection asks for the ads_read, ads_management and business_management permissions.
After you pick an ad account, Lumy may read:
Changes to your campaigns. The ads_management permission lets Lumy change campaigns in your ad account. Lumy analyzes campaigns, proposes changes and executes them after your approval. In the direct connection, the only change available today is pausing or resuming a campaign. Each such change needs your confirmation, and Lumy first checks that the campaign belongs to the ad account you picked. Through Windsor.ai and Google Ads, Lumy makes a change after you approve it, or when you have turned on that type of change yourself in Lumy's permission settings.
Storage and retention. Meta gives us an access token for the direct connection. We store it, together with the selected account details, in our AWS database in Frankfurt (eu-central-1). The database encrypts stored data with AWS Key Management Service. We keep the token and account details while the connection is in place. Data Lumy reads from Meta is kept under the rules in Section 9.
Removing access and deleting data. You can remove AdLume's access at any time in your Facebook or Meta Business settings; for a Windsor.ai connection, remove Windsor.ai there. This stops new reads, but it does not delete data we already hold. To delete that data, follow Section 9.1 or our data deletion page.
We may send relevant prompts, business context, account data, and user instructions to Anthropic, accessed through Amazon Bedrock in the EU, to generate outputs for the Service.
We do not intentionally send raw credentials, OAuth tokens, API keys, or payment card numbers to AI providers.
Your connected account data is not intentionally used to train general AI models for unrelated third-party use. Where an AI provider offers enterprise, API, or business data controls, we aim to use configurations that restrict provider training on customer data.
AI outputs may be incomplete, inaccurate, or inappropriate for your specific situation. Our Terms of Use explain your responsibility for reviewing, approving, and monitoring recommendations and automated actions.
We are based in Poland, but some providers and connected platforms may process data outside the EU/EEA, including in the United States.
Where required, we rely on appropriate transfer mechanisms such as:
Details of applicable transfer mechanisms are available on request where required by law.
We keep data only as long as reasonably necessary for the purposes described in this Policy, unless a longer retention period is required or permitted by law.
| Data Type | Typical Retention |
|---|---|
| Account and profile data | While your account is active and for up to 2 years after closure or last activity, unless earlier deletion is required or requested |
| Free audit eligibility record | Aby zapobiegać wielokrotnemu korzystaniu z bezpłatnego audytu, przechowujemy wyłącznie jednokierunkowo spseudonimizowany identyfikator workspace'u oraz informację i datę bezpłatnego audytu, które są automatycznie usuwane po 24 miesiącach. To prevent repeated use of the free audit, we retain only a one-way pseudonymized workspace identifier and information about and the date of the free audit; these are automatically deleted after 24 months. |
| Connected ad, analytics, marketing, ecommerce, and communication data | We retain connected-service data for as long as needed to provide the Service. When you use Lumy’s Google disconnect control, the defined local Google data is removed if the deletion process completes successfully; revoking access only in your Google Account settings does not currently trigger automatic deletion of local data. When you use Lumy’s Meta disconnect control on a Windsor.ai connection, we ask Windsor.ai to stop sharing that account and remove the Windsor.ai access key and account details from our records; data Lumy already read may remain until you delete your workspace. For a direct Meta connection, deleting your workspace removes the access token and selected account details. Removing AdLume's access only in your Facebook or Meta Business settings does not trigger automatic deletion of local data. Deleted database history may remain restorable in AWS backups for 35 days. |
| AI inputs, outputs, recommendations, approvals, and action logs | While needed to provide history, auditability, support, security, and product improvement; typically up to two years unless otherwise agreed |
| Payment, invoice, tax, and accounting records | As required by Polish accounting and tax law, typically 5 years or longer if required |
| Website and product analytics | Typically up to two years, unless configured differently or anonymized |
| Marketing email data | Until you unsubscribe or request deletion, subject to suppression lists and legal recordkeeping |
| Support and email communications | Typically up to 3 years, unless needed for legal, security, or dispute purposes |
| Security logs and technical diagnostics | We currently retain CloudWatch application logs for no longer than 30 days. Other diagnostic data may be retained for different periods where required for security, investigations, or compliance. |
If you request deletion, we will delete or anonymize eligible data unless retention is required for legal, billing, security, fraud prevention, dispute resolution, or legitimate business purposes. Removing Lumy from Slack attempts to revoke the Google token and disconnects Slack, but it does not by itself delete retained local data. Slack disconnect still proceeds if Google revocation fails. After deletion, database history may remain restorable in AWS Point-in-Time Recovery for 35 days.
These steps cover data from Google Ads, Meta Ads (through Windsor.ai or the direct connection), Slack and your workspace.
In the Lumy panel. The person who installed Lumy in the workspace can open the Lumy panel with the link Lumy sends in Slack, go to Settings, and in the Danger zone type the workspace name and choose Delete everything. Lumy then:
If deletion stops partway, the panel shows an error and some data may still exist. In that case, email us and we will finish the deletion by hand.
By email. Write to contact@adlume.co. Include the workspace name and the ad accounts the request covers. We may ask you to confirm that you can act for the workspace. We handle requests within the time limits set by the GDPR.
At Meta. Deleting data at AdLume does not remove AdLume's permission at Meta. To remove it, go to your Facebook or Meta Business settings and remove AdLume. For a Windsor.ai connection, remove Windsor.ai there as well.
What we keep. We keep invoices and tax records for as long as Polish law requires. Deleted database history may remain restorable in AWS backups for 35 days.
We use cookies and similar technologies to:
Types of cookies and similar technologies may include:
| Type | Purpose |
|---|---|
| Essential | Authentication, security, session management, checkout, and core functionality |
| Analytics | Product and website usage analysis, diagnostics, performance measurement |
| Marketing / advertising | Attribution, remarketing, campaign measurement, audience building where allowed |
| Preferences | Remembering settings and interface choices |
Where required by law, we ask for consent before using non-essential cookies or tracking technologies. You can also manage cookies through your browser settings. Disabling essential cookies may affect the functionality of the Service.
Depending on where you live, you may have rights to:
To exercise your rights, contact us at contact@adlume.co.
If you are in the EU/EEA and are not satisfied with our response, you may lodge a complaint with the Polish Data Protection Authority (UODO): https://uodo.gov.pl.
You may unsubscribe from marketing emails at any time using the unsubscribe link in the email or by contacting contact@adlume.co.
We may still send transactional or service-related messages, including account, billing, security, integration, policy, and support messages.
We use technical and organizational measures designed to protect data, including:
No system is 100% secure. If we become aware of a personal data breach that creates a risk to your rights and freedoms, we will notify affected users and the relevant supervisory authority where required by law.
The Service is not intended for individuals under 18. We do not knowingly collect personal data from minors. If we discover that we have collected data from a minor, we will delete it where required.
We may update this Privacy Policy from time to time. If changes are material, we will provide reasonable notice by email, in-app message, website notice, or another appropriate method.
The current version is available at https://adlume.co/privacy.
For privacy questions or rights requests:
Marek Dąbrowski, conducting business as AdLume
ul. Stawki 2a/38, 00-193 Warsaw, Poland
NIP: 1133071063
Email: contact@adlume.co
Website: https://adlume.co
This Privacy Policy was last reviewed on September 29, 2026.